Critical Bug Found In WordPress Plugin For Elementor With Over A Million Installations
A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.
The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.
"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."
That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.
The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."
The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.
Related articles
- Hacking Tools Software
- Pentest Tools Website Vulnerability
- Pentest Tools Download
- Hack Tools Mac
- Hacker Tools Apk
- Hackers Toolbox
- Pentest Tools Linux
- Kik Hack Tools
- Black Hat Hacker Tools
- What Is Hacking Tools
- New Hacker Tools
- Pentest Tools Windows
- Pentest Tools For Windows
- Pentest Reporting Tools
- Hack Tools Pc
- Android Hack Tools Github
- Pentest Tools
- Hack Tools For Ubuntu
- Hack Tools Pc
- Hacking Tools Online
- Hack Tools For Pc
- Best Pentesting Tools 2018
- Pentest Tools Github
- What Is Hacking Tools
- Hacker Tools Free Download
- Hack Tools
- How To Make Hacking Tools
- Hacking Tools For Mac
- Tools 4 Hack
- Nsa Hacker Tools
- Hack Tools
- New Hacker Tools
- Hack Tools Github
- Pentest Tools Online
- New Hacker Tools
- Underground Hacker Sites
- Tools Used For Hacking
- Pentest Tools Review
- What Is Hacking Tools
- Hack Tools Online
- Blackhat Hacker Tools
- Hacking Tools Windows
- New Hack Tools
- Hacker Tool Kit
- Hacker Tools Online
- Usb Pentest Tools
- Android Hack Tools Github
- Hacking Tools Github
- Wifi Hacker Tools For Windows
- Hacking Tools Github
- Hackers Toolbox
- Pentest Tools Online
- Hacker Security Tools
- Hacker Search Tools
- Hacker Tools 2020
- Hack App
- Hacker Tools Mac
- Pentest Tools Review
- Hacker Tools Free Download
- Top Pentest Tools
- Best Hacking Tools 2020
- Github Hacking Tools
- Hak5 Tools
- Hack Tools For Mac
- Hack Tools Download
- Easy Hack Tools
- Pentest Box Tools Download
- Hack Tools For Mac
- Hacker Tools Linux
- Hacker Tools Apk
- Pentest Tools Linux
- Tools 4 Hack
- Pentest Tools Kali Linux
- Hack And Tools
- Pentest Tools For Mac
- Pentest Tools Bluekeep
- Hacking Tools For Beginners
- Pentest Tools Subdomain
- Beginner Hacker Tools
- Hack Tools 2019
- What Is Hacking Tools
- Pentest Tools Free
- Hacker Tools Linux
- Pentest Tools Windows
- Install Pentest Tools Ubuntu
- Hacker Tools Apk
- Pentest Tools Github
- Hack Tools
- Hacking Tools For Windows Free Download
- Pentest Tools Open Source
- Pentest Tools For Mac
- Hacking Tools Software
- Ethical Hacker Tools
- Hacking App
- Pentest Reporting Tools
- Pentest Tools Android
- Hak5 Tools
- Growth Hacker Tools
- Hacker Tools Apk Download
- Hacking Apps
- Best Pentesting Tools 2018
- Hacker Search Tools
- Hacker Tools Software
- Bluetooth Hacking Tools Kali
- What Is Hacking Tools
- Pentest Tools Kali Linux
- Game Hacking
- Hack Tools Online
- Hacking Apps
- Hacker Tools For Ios
- Hacker Tools 2020
- Pentest Tools For Android
- Pentest Tools For Windows
- Hacking Tools For Pc
- What Are Hacking Tools
- Pentest Tools Framework
- Hacker Tools Apk
- Hacking Tools 2019
- Hack Tools Github
- Hacker Tools Apk
- Hacker Tools List
- Github Hacking Tools
- Hacking Tools Kit
- Hack Rom Tools
- Hacking Tools For Windows 7
- Pentest Tools Tcp Port Scanner
- Pentest Tools Apk
- Nsa Hacker Tools
- Hack Tools Github
- Termux Hacking Tools 2019
- Pentest Tools For Windows
- Pentest Tools Open Source
- Hacker Tools For Windows
- Github Hacking Tools
- Hacking Tools Free Download
- Hacking Tools Kit
- Hacker Tools Software
- Hacker
- Hacking Tools Hardware
- Hacking Tools For Games
- Best Hacking Tools 2020
- Pentest Tools Subdomain
- Blackhat Hacker Tools
- Hacker Tools Windows
- Hacking Tools
- Pentest Tools Website Vulnerability
- Tools 4 Hack
- Pentest Tools Linux
- Hacking Tools Mac
- Hack Tools For Mac
- Pentest Tools Android
- Hacker Tools Apk
- Hacking Tools For Mac
- Pentest Tools Windows
0 Comments:
Publicar un comentario
<< Home